Outbound Wiki

Article

GDPR Email Marketing: A Practical Compliance Checklist (2026)

migomail.com

Open at publisher

Quoted on this wiki

Every place a page here uses this source, in the order the words come in it.

  1. Requirement GDPR (EU / UK) CAN-SPAM (USA) CASL (Canada) Lawful basis required ✅ Yes — one of six bases ❌ No ✅ Yes — express or implied consent Prior consent for marketing ✅ Yes (consent basis) ❌ No ✅ Yes Consent documentation ✅ Yes — timestamp, method, wording ❌ No ✅ Yes Pre-checked boxes permitted ❌ No ✅ Yes ❌ No Right to erasure ✅ Yes — within 30 days ❌ No ✅ Limited Right of access (SAR) ✅ Yes — within 30 days ❌ No ❌ No Unsubscribe required ✅ Yes ✅ Yes ✅ Yes Unsubscribe processing time Without undue delay 10 business days 10 business days DPA with email platform ✅ Required ❌ No ❌ No Maximum fine €20M or 4% global revenue $51,744 per email $10M CAD per violation For a US business with global subscribers, apply GDPR to UK and EU subscribers, CAN-SPAM to US subscribers, and CASL to Canadian subscribers. GDPR Email Marketing Compliance Checklist

    In Cross-border outbound adaptation

  2. What is the difference between a GDPR unsubscribe and an erasure request? An unsubscribe stops marketing email — the subscriber's email address remains in your suppression list and their data may remain in your CRM for other legitimate purposes. An erasure request (right to be forgotten) requires you to delete all personal data you hold about the individual — from your email platform, CRM, analytics tools, and any other system — within 30 days. The only data you may retain after an erasure request is a suppression record (email address plus erasure date) to prevent the address from being re-added to your list. If a subscriber sends you an email asking you to "delete all my data," treat it as an erasure request regardless of whether they used that specific term. For B2B email marketing to individually identifiable business contacts in the EU or UK, GDPR applies. What are the fines for GDPR violations related to email marketing? GDPR fines are tiered: lower-tier violations can result in fines up to €10 million or 2% of global annual turnover, whichever is higher. Upper-tier violations — including processing personal data without a lawful basis, which covers sending marketing email without consent — can result in fines up to €20 million or 4% of global annual turnover, whichever is higher. UK GDPR provides for equivalent fines in GBP. The highest single fine issued to date was €1.2 billion against Meta in 2023. For email marketing specifically, fines have typically been issued for large-scale sending without consent, failure to honour unsubscribe requests, and inadequate consent mechanisms. Small businesses are not typically subject to maximum fines for first-time or inadvertent violations, but enforcement risk is real.

    In GDPR territorial scope